Mar 03 2011

Facebook Account Hack: Spam 80,000 friends

Category: social engineering,Social networkDISC @ 1:05 pm

by Sandy Sidhu

Social media is hot. 140 characters is the way to communicate these days and it’s not unusual to hear someone say, “I have 3000 friends.”

We often hear about the success stories, but what about the unsuccessful ones?

Take Jonathan Emile, a Montreal-based hip-hop artist, who has made his living building a fan base online and uses Facebook to communicate with his 80,000 fans. Yeah, you read that right: 80,000.

You can imagine his frustration when last week he was unable to login to his account, leading him to believe his account had been hijacked, likely by a spammer, or a robot software program designed by a spammer. His suspicions were reinforced when he saw someone had used his name to post a link on his fan page site, that Emile said appeared to be malicious: either a virus or spam.

Despite contacting Facebook, he still has not been able to access his account.

So what can you learn from this ?

•Make sure you have other ways to contact and connect with your fans/customers/subscribers, and so on
•Use strong passwords and regularly change them
•Don’t rely on a third party platform to run the bulk of your business!
Facebook and other sites constantly change their Privacy Policies and access rules, not to mention the fact that they may not always be around (remember MySpace?).

Social networking is a great way to reach a new audience, but you have to make sure that you can still communicate with that audience through other means should anything go wrong. It is a good place to get people to interact with you/your company/brand, but you should also encourage your “fans” to either sign up for a newsletter, eBook, and so on, as a way to capture their information and ultimately drive them back to your site, which (hopefully) you own.

Risk management of Facebook – benefits, risks and possible countermeasures


Mar 02 2011

GPS ON CELL PHONES CAMERAS a PRIVACY ISSUE

Category: Information PrivacyDISC @ 3:08 pm

Big GOVERNMENT & CRIMINALS ADVANTAGE OVER US

  • Anyone who’s posted cell photos online: The bad guys can now tell the EXACT location where photos were taken.




  • more on how privacy is at risk and possible safeguards


    Feb 28 2011

    Is the next generation Firewall in your Future?

    Category: App Security,Firewall,next generation firewallDISC @ 3:02 pm

    Download a Free copy of “Next-Generation Firewalls for Dummies” ebook to find out why traditional firewalls can’t protect your network | Checkout the sample chapter online

    By Ellen Messmer

    The traditional port-based enterprise firewall, now looking less like a guard and more like a pit stop for Internet applications racing in through the often open ports 80 and 443, is slowly losing out to a new generation of brawny, fast, intelligent firewalls.

    The so called next-generation firewall (NGFW) describes an enterprise firewall/VPN that has the muscle to efficiently perform intrusion prevention sweeps of traffic, as well as have awareness about the applications moving through it in order to enforce policies based on allowed identity-based application usage. It’s supposed to have the brains to use information such as Internet reputation analysis to help with malware filtering or integrate with Active Directory.

    But how long will it take for the NGFW transition to truly arrive?

    To read the full article …..

    Download free ebook for next gereration firewall how it may protect your information assets

    Download a Free copy of “Next-Generation Firewalls for Dummies” ebook to find out why traditional firewalls can’t protect your network | Checkout the sample chapter online

    Tags: Application security, IDS, IPS, NGFW


    Feb 28 2011

    Does hacker insurance make your business a bigger liability?

    Category: Cyber InsuranceDISC @ 11:44 am

    by Davey Winder

    It’s a scenario that every small online business fears: site security is compromised, hackers steal customer data including credit-card details, and your brand and your reputation are left in ruins. No wonder then, that many small online businesses are looking to insure against hackers and the resulting financial impact of a security breach. But is insurance really the answer and could it even be part of the problem?

    The insurance brokers are, naturally, presenting such insurance as pure common sense. A chap who works in the insurance business used car insurance as a counter argument to my suggestion that surely the best IT security insurance policy was to remain secure in the first place.

    “We all appreciate the need for car insurance” he told me. “No matter how careful a driver you may think you are. The simple fact is that you never know when a drunken idiot is going to crash into you”.

    The argument being, as with all insurance policies, you are paying a premium to cover you for that worst-case scenario should it ever happen. “When it comes to online security,” Mr Insurance assured me, “the chances of the worst-case scenario becoming a reality are increasing day by day, as criminals develop ever more sophisticated methods of hacking your site. To not insure against the risk of being hacked is bad business, and that’s the bottom line”.

    “Unlike driving a car, running a secure web business is pretty much about how safe you are, rather than how unsafe other people are”

    To read the reamining article …..

    How to manage the gaps of Cyber Insurance

    Tags: hacker, Hacking, Insurance, Security, Small business


    Feb 22 2011

    Businesses deemed lack of security a major concern for cloud computing

    Category: Cloud computingDISC @ 11:06 pm
    Diagram showing three main types of cloud comp...

    Image via Wikipedia

    By NICK CLAYTON – WSJ.com
    As the much-hyped next big thing in information technology, the cloud in cloud computing seems almost too apt as a metaphor. Constantly moving and changing, impossible to pin down and the closer it gets, the harder it is to distinguish from fog.

    It has divided opinion. On one side are those who believe the cloud represents nothing less than a revolution that will bring a golden age of cheap, efficient and agile computing on tap. Lined up against them are skeptics who have seen variations on these promises for decades, which have never been fully delivered. However, the single biggest concern weighing on the minds of those chief executives looking to embrace cloud technology is security. Once businesses are happy their data is truly safe in the cloud, only then will this technology transform the world.

    To read the remaining article….

    How to manage risks in the world of cloud computing

    How to manage risks in the world of cloud computing


    Feb 17 2011

    RSA conference looks at online vulnerability

    Category: cyber security,Smart PhoneDISC @ 5:27 pm

    By James Temple

    The hottest trends in technology also represent some of the gravest threats to corporate data security.

    Mobile devices, social networking and cloud computing are opening up new avenues for both cyber criminals and competitors to access critical business information, according to speakers at this week’s RSA Conference 2011 at San Francisco’s Moscone_Centerand a survey set for release this morning.

    The poll of 10,000 security professionals, by Mountain View market research firm Frost & Sullivan, also concluded that corporate technology staffs are frequently ill prepared to deal with many of the new threats presented by these emerging technologies.

    “The professionals are really struggling to keep up,” said Rob Ayoub, global program director for information security research at Frost & Sullivan.

  • Mobile: Mobile devices ranked near the top of their security concerns, coming in second behind applications, such as internally developed software and Internet browsers.
  • Businesses face a number of threats from the increasingly common use of smart phones and tablets by their workers, including malicious software that attacks the operating systems, or the simple loss or theft of devices often laden with corporate information.

    Juniper Networks, a sponsor of the RSA conference, presented some eye-catching – if also self-serving – statistics during a session titled “Defend Your Mobile Life.”

    Mark Bauhaus, an executive vice president at Juniper, said that 98 percent of mobile devices like smart phones and tablets aren’t protected with any security software, and that few users set up a password. That’s troublesome, he said, given that:

    — 2 million people in the United States either lost or had their phones stolen last year;

    — 40 percent of people use their smart phone for both personal and business use;

    — 72 percent access sensitive information, including banking, credit card and medical records;

    — 80 percent access their employer’s network over these devices without permission.

    Read more: New Technologies bring new threats

    Mobile devices new threats and countermeasures


    Feb 10 2011

    China-based hackers targeted oil, energy companies in ‘Night Dragon’ cyber attacks

    Category: cyber securityDISC @ 8:34 pm
    Utility

    Image by lisbokt via Flickr

    From the LA Times

    China-based hackers may have been stealing sensitive information from several international oil and energy companies for as long as four years, cyber-security firm McAfee Inc. said in a report Thursday.

    The company said it traced the “coordinated covert and targeted cyberattacks” back to at least November 2009 and that victims included companies in the U.S., Taiwan, Greece and Kazakhstan. McAfee has dubbed the security breach “Night Dragon.”

    McAfee said the hackers, using techniques and tools originating in China and often found on Chinese hacking forums, grabbed details about company operations, project financing and bidding that “can make or break multibillion dollar deals.”

    Operating through servers in the U.S. and the Netherlands, the company said, the hackers exploited vulnerabilities in the Microsoft Windows operating system. Techniques included social engineering, spear-phishing, Active Directory compromises and remote administration tools, or RATs.

    Although elaborate, Santa Clara-based McAfee said the hacking method was “relatively unsophisticated.” And because most of the Night Dragon attacks originated between 9 a.m. and 5 p.m. Beijing time on weekdays, the cyber-security firm said it suspects that the hacking was not the work of freelancers.

    Tags: Active Directory, china, Greece, Kazakhstan, McAfee, Microsoft Windows, phishing, Taiwan


    Feb 01 2011

    Top 15 hacking tools & utilities

    Category: cyber securityDISC @ 1:05 pm

    A list of 15 Hacking Tools & Utilities from darknet.org.uk.

    Experienced user may recognize most of these tools and for others who are not so familir with these tools may provode a good place to start with a good explanation.

    Here is a short list of all the other tools mentioned: Nmap, Nessus Remote Security Scanner, John the Ripper, Nikto, Superscan, pof, Ethereal, Yersinia, LCP, Cain and Abel, Kismet, Netstumbler and hping.

    Make sure you check these tools in a safer environment and have a proper authorization to use these tools on a client or business environment.

    Here is a list again 15 Hacking Tools & Utilities for your review. Please share your thought on some your favorite tools which works for you.

    To know more the latest titles on security tools


    Jan 27 2011

    Cyber Attacks Jeopardize Superpower Status

    Category: cyber securityDISC @ 3:09 pm

    Cyberspace enable e-mail, electricity grids, international banking and military superiority.
    We can’t live without cyberspace – but increasingly, experts say its openness is putting the United States in jeopardy.

    “We can say that sovereignty’s at risk,” said Sami Saydjari. He heads the Cyber Defense Agency, an information security company.

    “Basically our whole superpower status as the United States depends on computers,” he said. “We lose them, we lose our status as a superpower. We become a Third World country overnight.”

    http://www.youtube.com/watch?v=V3rNiKF4ku8

    Tags: Cyber Defense Agency, Cyber-warfare, cyberwar, Sami Saydjari, superpower status


    Jan 25 2011

    Cisco Security Report Says Unemployed Are Targeted By Money Mules

    Category: CybercrimeDISC @ 5:26 pm

    By Samuel Rubenfeld

    Add another burden to being unemployed: Those seeking work are increasingly targeted by money mules for laundering operations.

    The “Cisco 2010 Annual Security Report,” (pdf) released Thursday, says that alongside ongoing threats from phishing attempts, viruses, trojans and more, the unemployed–or the underemployed–may become unsuspecting conduits for money laundering. This can happen through “work-from-home” scams where a person’s “job” is to receive items, repackage them and ship them abroad, not knowing that the items were obtained illegally using stolen or fraudulent credit cards that further the money laundering operation.

    “People scouring employment ads on legitimate, well-known job search sites also have been duped by these scams,” the report says, later adding: “Individuals who come in contact with these operations usually have no idea they are being recruited as money mules, and believe they are dealing with a recruiter for a legitimate company.”

    Titles below explain how money laundering works…

    Tags: money laundering, money mules


    Jan 19 2011

    Zeus Toolkit Gangs Staging Mass Attacks on Banking Applications

    Category: App Security,CybercrimeDISC @ 11:12 am

    Since 2007, illicit organizations have employed Zeus to launch damaging, highly publicized attacks targeting the login credentials and other personal data associated with millions of computers, thousands of organizations, and uncounted numbers of users and their accounts. Relatively small groups of sophisticated criminal bands based in various nations–particularly in Eastern European countries such as Russia and Ukraine–have stolen tens of millions of dollars. Computers in 196 countries have been subject to attack. The countries most affected include the U.S., U.K., Saudi Arabia, Egypt, and Turkey.

    To read the full article ….


    Jan 13 2011

    Meet Stringent California Information Security Legislation with Comprehensive Toolkit

    Category: ISO 27kDISC @ 4:06 pm

    Three years ago, California state IT council adopted the information security program guide which help organizations to comply with SB 1386. The council advised the use of information security standard ISO 27002 framework to comply and meet the needs of SB 1386.

    This legislation deals with the security of personal information and is applicable to all organisations (state and government agencies, non-profit, companies of all sizes, regardless of geographic location) holding personal data on any person living in California. SB-1386 requires such information holders to disclose any unauthorised access of computerised data files containing personal information.

    In response, IT Governance’s comprehensive ‘SB-1386 & ISO27002 Implementation Toolkit’ is specifically designed by experts in data compliance legislation to guide organisations on how to conform to SB-1386. The toolkit conforms to ISO27002 and, if desired, also helps organisations prepare for any external certification process (ISO 27001) that would demonstrate conformance with such a standard. The State of California has itself formally adopted ISO/IEC 27002 as its standard for information security and recommended that organisations use this standard as guidance in their efforts to comply with California law.


    Which businesses are affected by SB 1386 law?
    o If you have a business in California
    o Outsourcing company who does business with a company in California or have customers in California
    o Data centers outside of California which store information of California residents

    sb1386

    Toolkits are designed to help organizations who need to comply with a law like SB 1386. SB 1386 and ISO 27002 implementation toolkit assist ISO 27002 compliance. Also help organizations who are interested in certification to lay in the ground work for (ISO 27001) certification that would demonstrate the conformance with world class information security management systems.


    The Comprehensive SB1386 Implementation toolkit comprises of:
    1. The SB 1386 Documentation Toolkit: a download with nearly 400 of densely packed pages of fit-for-purpose policies and procedures ensuring full compliance with SB 1386.
    2. International IT Governance: An Executive Guide to ISO 17799/ISO 27001 (Soft Cover) This is the US version of the long established world leading manual on designing and implementing an Information Security Management System (ISMS) in line with the best practice guidance of ISO27001/ISO17799.
    3. vsRisk™- the Definitive ISO 27001: 2005-Compliant Information Security Risk Assessment Tool which in summary:
    o automates and delivers an ISO/IEC 27001-compliant risk assessment
    o Uniquely, can assess confidentiality, integrity & availability for each of business, legal and contractual aspects of information assets – as required by ISO 27001
    o Comprehensive best-practice alignment
    o Supports ISO 27001
    o Supports ISO 27002 (ISO/IEC 17799)
    o Conforms to ISO/IEC 27005
    o Conforms to NIST SP 800-30
    o The wizard-based approach simplifies and accelerates the risk assessment process;
    o Integrated, regularly updated, BS7799-3 compliant threat and vulnerability databases.
    4. Plus an electronic copy of the Information Security Standard ISO/IEC 27002: (formerly ISO 17799).

    Buy The SB-1386 & ISO27002 Implementation Toolkit NOW!

    ISO assessment is a great first step towards ISO 27002 compliance and toward the final goal of ISO 27001 certification.

    vsRisk and security risk assessment

    ISO 27002 Framework for Today’s Security Challenges
    httpv://www.youtube.com/watch?v=yRFMfiLbNj8

    Tags: iso 27001, iso 27001 certification, iso 27002, iso 27005, ISO 27k, iso assessment, iso compliance, sb 1386


    Jan 11 2011

    Biggest mobile malware threat

    Category: Malware,Smart Phone,Web 2.0DISC @ 2:39 pm
    Image representing Facebook as depicted in Cru...
    Image via CrunchBase

    Facebook is biggest mobile malware threat, says security firm
    Researcher claims bad links on Facebook responsible for much higher infection rate that targeted mobile malware

    By Joan Goodchild -CSO

    The biggest mobile infection threat isn’t malware that specifically targets mobile devices, according to new research from security firm BitDefender. Malware that targets Facebook is a far bigger problem for mobile security, the firm claims.

    Spam links on social networks are infecting mobile devices via bad links on Facebook because the worms and other malware are often platform-independent and are widely spread as malware that targets PCs.

    BitDefender officials point to Google statistics, which reveal almost one quarter of Facebook users who fell for a recent scam on the social network did so from their mobile device. The URL that was studied was one that claimed to show users a girl’s Facebook status which got her expelled from school. It generated 28,672 clicks — 24 percent of which originated from mobile platforms. Users who clicked on the link — whether on their PC or mobile device — downloaded a Facebook worm and fell victim to an adword-based money grabbing scheme.

    “When data security researchers focus on finding malware specifically designed for mobile platforms, they lose sight of an important mobile platform threat source — the social network,” said George Petre, BitDefender Threat Intelligence Team Leader.

    Mobile Malware Attacks and Defense

    The Truth About Facebook – Privacy Settings Every Facebook User Should Know, and Much More – The Facts You Should Know

    Tags: facebook, Google, Koobface, Malware, Mobile device, Mobile operating system, Social network, Uniform Resource Locator


    Jan 09 2011

    Information Systems Security

    Category: CISSP,Information SecurityDISC @ 1:20 pm

    CISSP: Certified Information Systems Security Professional Study Guide

    CISSP: Certified Information Systems Security Professional Study Guide

    Totally updated for 2011, here’s the ultimate study guide for the CISSP exam
    Considered the most desired certification for IT security professionals, the Certified Information Systems Security Professional designation is also a career-booster. This comprehensive study guide covers every aspect of the 2011 exam and the latest revision of the CISSP body of knowledge. It offers advice on how to pass each section of the exam and features expanded coverage of biometrics, auditing and accountability, software security testing, and other key topics. Included is a CD with two full-length, 250-question sample exams to test your progress.

    CISSP certification identifies the ultimate IT security professional; this complete study guide is fully updated to cover all the objectives of the 2011 CISSP exam
    Provides in-depth knowledge of access control, application development security, business continuity and disaster recovery planning, cryptography, Information Security governance and risk management, operations security, physical (environmental) security, security architecture and design, and telecommunications and network security
    Also covers legal and regulatory investigation and compliance
    Includes two practice exams and challenging review questions on the CD
    Professionals seeking the CISSP certification will boost their chances of success with CISSP: Certified Information Systems Security Professional Study Guide, 5th Edition.

    From the Back Cover
    Comprehensive preparation for the 2011 CISSP certification exam

    With pages of in-depth coverage, real-world scenarios, and detailed explanations of all domains from the Common Body of Knowledge (CBK) for the CISSP certification exam, this complete guide not only thoroughly prepares you for the exam, it also helps you develop practical skills for success on the job. Key topics include access control, business continuity, cryptography, biometrics, and more. You’ll also find helpful advice on how to pass each section of the exam. Inside, find:

    Full coverage of all exam objectives in a systematic approach, so you can be confident you’re getting the instruction you need for the exam

    Real-world scenarios that put what you’ve learned in the context of actual job roles

    Challenging review questions in each chapter to prepare you for exam day

    Exam Essentials, a key feature in each chapter that identifies critical areas you must become proficient in before taking the exam

    A handy tear card that maps every official exam objective to the corresponding chapter in the book, so you can track your exam prep objective by objective

    Look inside for complete coverage of all exam objectives.

    SYBEX TEST ENGINE

    Test your knowledge with advanced testing software. Includes all chapter review questions and two full-length, 250-question practice exams.

    ELECTRONIC FLASHCARDS

    Reinforce your understanding with electronic flashcards.

    Also on CD, you’ll find the entire book in searchable and printable PDF. Study anywhere, any time, and approach the exam with confidence.

    Includes Real-World Scenarios, Written Labs, and

    Leading-Edge Exam Prep Software Featuring:

    Custom Test Engine

    Two Full-Length, 250-Question Practice Exams

    Electronic Flashcards

    Entire Book in PDF

    Tags: CISSP book, CISSP book recommendation, information systems security


    Jan 06 2011

    The Basics of Stuxnet Worm and How it infects PLCs

    Category: MalwareDISC @ 1:01 pm
    Future of Mobile Malware & Cloud Computing Key...
    Image by biatch0r via Flickr

    Considered to be the most intricately designed piece of malware ever, Stuxnet leverages attack vectors onto industrial control systems, a territory rarely ventured into by traditional malware. Stuxnet targets industries, power plants and other facilities that use automation and control equipment from the leading German industrial vendor, Siemens. The term, critical infrastructure refers to industrial systems that are essential for the functioning and safety of our societies. Considering the profound dependence of critical infrastructure on industrial control and automation equipment, it is essential to reassess the impact this new generation of malware on the stability and security of our society.

    Download WhitePaper

    Has Israel Begun A Cyber War On Iran With The Stuxnet ‘Missile’?: An article from: APS Diplomat News Service

    The New Face of War: How War Will Be Fought in the 21st Century

    Tags: Business, Control system, Critical infrastructure, Industrial control systems, Iran, Malware, Siemens, Symantec


    Jan 06 2011

    Security 2020: Reduce Security Risks This Decade

    Category: Information SecurityDISC @ 10:59 am

     

    Security 2020: Reduce Security Risks This Decade

    Identify real security risks and skip the hype. After years of focusing on IT security, we find that hackers are as active and effective as ever. This book gives application developers, networking and security professionals, those that create standards, and CIOs a straightforward look at the reality of today’s IT security and a sobering forecast of what to expect in the next decade. It debunks the media hype and unnecessary concerns while focusing on the knowledge you need to combat and prioritize the actual risks of today and beyond.

    IT security needs are constantly evolving; this guide examines what history has taught us and predicts future concerns
    Points out the differences between artificial concerns and solutions and the very real threats to new technology, with startling real-world scenarios
    Provides knowledge needed to cope with emerging dangers and offers opinions and input from more than 20 noteworthy CIOs and business executives
    Gives you insight to not only what these industry experts believe, but also what over 20 of their peers believe and predict as well

    With a foreword by security expert Bruce Schneier, Security 2020: Reduce Security Risks This Decade supplies a roadmap to real IT security for the coming decade and beyond.

    Order this book for advice on how to reduce IT security risks on emerging threats to your business in coming years. Security 2020: Reduce Security Risks This Decade

    From the Back Cover
    Learn what’s real, what’s hype, and what you can do about it
    For decades, security experts and their IT peers have battled the black hats. Yet the threats are as prolific as ever and more sophisticated. Compliance requirements are evolving rapidly and globalization is creating new technology pressures. Risk mitigation is paramount. What lies ahead?

    Doug Howard and Kevin Prince draw upon their vast experience of providing security services to many Fortune-ranked companies, as well as small and medium businesses. Along with their panel of security expert contributors, they offer real-world experience that provides a perspective on security past, present, and future. Some risk scenarios may surprise you. Some may embody fears you have already considered. But all will help you make tomorrow’s IT world a little more secure than today’s.

    Over 50 industry experts weigh in with their thoughts

    Review the history of security breaches

    Explore likely future threats, including social networking concerns and doppelganger attacks

    Understand the threat to Unified Communication and Collaboration (UCC) technologies

    Consider the impact of an attack on the global financial system

    Look at the expected evolution of intrusion detection systems, network access control, and related safeguards

    Learn to combat the risks inherent in mobile devices and cloud computing

    Study 11 chilling and highly possible scenarios that might happen in the future

    Tags: Bruce Schneier, Computer security, Consultants, Doug Howard, Intrusion detection system, Kevin Prince, Security, United States


    Jan 04 2011

    Electronic Pick Pocketing with RFID

    Category: Cybercrime,pci dssDISC @ 9:10 am

    RFID Security

    Thieves now have the capabilities to steal your credit card information without laying a hand on your wallet.

    It’s new technology being used in credit and debit cards, and it’s already leaving nearly 140 million people at-risk for electronic pickpocketing.

    It all centers around radio frequency identification technology, or RFID.

    You’ll find it in everything from your passports to credit and debit cards.

    It’s supposed to make paying for things faster and easier.

    You just wave the card, and you’ve paid.

    But now some worry it’s also making life easier for crooks trying to rip you off.

    In a crowd, Walt Augustinowicz blends right in.

    And that’s the problem.

    “If I’m walking through a crowd, I get near people’s back pocket and their wallet, I just need to be this close to it and there’s my credit card and expiration date on the screen,” says Augustinowicz demonstrating how easily cards containing RFID can be hacked.

    Armed with a credit card reader he bought for less than $100 on-line and a netbook computer.

    RFID Security

    Tags: credit card fraud, electronic pick pocketing


    Jan 03 2011

    New virus threatens phones using Android

    Category: MalwareDISC @ 5:39 pm
    it's real :)
    Image via Wikipedia

    Mobile Malware Attacks and Defense

    WASHINGTON (AFP) – A virus infecting mobile phones using Google’s Android operating system has emerged in China that can allow a hacker to gain access to personal data, US security experts said.

    A report this week from Lookout Mobile Security said the new Trojan affecting Android devices has been dubbed “Geinimi” and “can compromise a significant amount of personal data on a user?s phone and send it to remote servers.”

    The firm called the virus “the most sophisticated Android malware we’ve seen to date.”

    “Once the malware is installed on a user’s phone, it has the potential to receive commands from a remote server that allow the owner of that server to control the phone,” Lookout said.

    “Geinimi’s author(s) have raised the sophistication bar significantly over and above previously observed Android malware by employing techniques to obfuscate its activities.”

    The motive for the virus was not clear, accoring the Lookout, which added that this could be used for anything from “a malicious ad-network to an attempt to create an Android botnet.”

    But the company said the only users likely to be affected are those downloading Android apps from China.

    The infected apps included repackaged versions sold in China of Monkey Jump 2, Sex Positions, President vs. Aliens, City Defense and Baseball Superstars 2010.

    “It is important to remember that even though there are instances of the games repackaged with the Trojan, the original versions available in the official Google Android Market have not been affected,” the security firm said.

    Mobile Malware Attacks and Defense

    Tags: Android, china, Google, Malware, mobile phone, Security, Servers, Trojan horse


    Dec 30 2010

    Information Security Law: The Emerging Standard for Corporate Compliance

    Category: Information Security,ISO 27kDISC @ 3:25 pm

    Order Information Security Law: The Emerging Standard for Corporate Compliance today!
    Information Security Law: The Emerging Standard for Corporate Compliance

    In today’s business environment, virtually all of a company’s daily transactions and all of its key records are created, used, communicated, and stored in electronic form using networked computer technology. Most business entities are, quite literally, fully dependent upon information technology and an interconnected information infrastructure.

    Emerging information security compliance requirements.
    While this reliance on technology provides tremendous economic benefits, it also creates significant potential vulnerabilities that can lead to major harm to a company and its various stakeholders. As a result, public policy concerns regarding these risks are driving the enactment of numerous laws and regulations that require businesses to adequately address the security of their own data.

    Information Security Law: The Emerging Standard for Corporate Compliance is designed to help companies understand this developing law of information security, the obligations it imposes on them, and the standard for corporate compliance that appears to be developing worldwide. ISO/IEC 27001, the international information security standard, should be read alongside this book.

    Emerging global legal framework – and compliance in multiple jurisdictions.
    This book takes a high level view of the multitude of security laws and regulations, and summarizes the global legal framework for information security that emerges from them. It is written for companies struggling to comply with several information security laws in multiple jurisdictions, as well as for companies that want to better understand their obligations under a single law. It explains the common approach of most security laws, and seeks to help businesses understand the issues that they need to address to become generally legally compliant.

    About the Author
    The author, Thomas J. Smedinghoff, is an attorney and partner in a Privacy, Data Security, and Information Law Practice in Chicago. He has been actively involved in developing e-business and information security legal policy, both in the US and globally. He currently serves as a member of the US Delegation to the United Nations Commission on International Trade Law (UNCITRAL) and chairs the International Policy Coordinating Committee of the American Bar Association (ABA) Section of Science & Technology Law.

    ORDER YOUR COPY OF THIS INFORMATIVE BOOK ON INFORMATION SECURITY LAW NOW….Information Security Law: The Emerging Standard for Corporate Compliance

    Author: Thomas J Smedinghoff
    Publisher: IT Governance Publishing
    Format: Softcover
    ISBN: 9781905356669

    Pages:185
    Published Date: 7th October 2008
    Availability: Immediate


    Dec 26 2010

    Information Security Risk Management for ISO27001/ISO27002

    Category: ISO 27k,Security Risk AssessmentDISC @ 8:56 pm

    Expert guidance on planning and implementing a risk assessment and protecting your business information. In the knowledge economy, organisations have to be able to protect their information assets. Information security management has, therefore, become a critical corporate discipline. The international code of practice for an information security management system (ISMS) is ISO27002. As the code of practice explains, information security management enables organisations to ‘ensure business continuity, minimise business risk, and maximise return on investments and business opportunities’.

    ISMS requirements
    The requirements for an ISMS are specified in ISO27001. Under ISO27001, a risk assessment has to be carried out before any controls can be selected and implemented, making risk assessment the core competence of information security management. This book provides information security and risk management teams with detailed, practical guidance on how to develop and implement a risk assessment in line with the requirements of ISO27001.

    International best practice
    Drawing on international best practice, including ISO/IEC 27005, NIST SP800-30 and BS7799-3, the book explains in practical detail how to carry out an information security risk assessment. It covers key topics, such as risk scales, threats and vulnerabilities, selection of controls, and roles and responsibilities, and includes advice on choosing risk assessment software.

    Benefits to business include:

    Stop the hacker. With a proper risk assessment, you can select appropriate controls to protect your organisation from hackers, worms and viruses, and other threats that could potentially cripple your business.

    Achieve optimum ROI. Failure to invest sufficiently in information security controls is ‘penny wise, pound foolish’, since, for a relatively low outlay, it is possible to minimise your organisation’s exposure to potentially devastating losses. However, having too many safeguards in place will make information security system expensive and bureaucratic; so without accurate planning your investment in information security controls can become unproductive. With the aid of a methodical risk assessment, you can select and implement your information security controls to ensure that your resources will be allocated to countering the major risks to your organisation. In this way, you will optimise your return on investment.

    Build customer confidence. Protecting your information security is essential if you want to preserve the trust of your clients and to keep your business running smoothly from day to day. If you set up an ISMS in line with ISO27001, then, after an assessment, you can obtain certification. Buyers now tend to look for the assurance that can be derived from an accredited certification to ISO27001 and, increasingly, certification to ISO27001 is becoming a prerequisite in service specification procurement documents.

    Comply with corporate governance codes. Information security is a vital aspect of enterprise risk management (ERM). An ERM framework is required by various corporate governance codes, such as the Turnbull Guidance contained within the UK’s Combined Code on Corporate Governance, and the American Sarbanes-Oxley Act (SOX) of 2002, and standards such as ISO310000.

    Order this book for advice on information security management that can really benefit your bottom line! Information Security Risk Management for ISO27001 / ISO27002

    About the authors

    Alan Calder is the founder director of IT Governance Ltd. He has many years of senior management and board-level experience in the private and public sectors.

    Steve G Watkins leads the consultancy and training services of IT Governance Ltd. In his various roles in both the public and private sectors he has been responsible for most support disciplines. He has over 20 years’ experience of managing integrated management systems, and is a lead auditor for ISO27001 and ISO9000. He is now an ISMS Technical Expert for UKAS, and provides them with advice for their assessments of certification bodies offering certification to ISO27001.


    « Previous PageNext Page »